Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:0883-1

Опубликовано: 17 мар. 2025
Источник: suse-cvrf

Описание

Security update for python312

This update for python312 fixes the following issues:

  • CVE-2025-1795: Fixed mishandling of comma during folding and unicode-encoding of email headers (bsc#1238450).

Список пакетов

Container bci/python:latest
libpython3_12-1_0-3.12.9-150600.3.21.1
python312-3.12.9-150600.3.21.1
python312-base-3.12.9-150600.3.21.1
python312-devel-3.12.9-150600.3.21.1
SUSE Linux Enterprise Module for Python 3 15 SP6
libpython3_12-1_0-3.12.9-150600.3.21.1
python312-3.12.9-150600.3.21.1
python312-base-3.12.9-150600.3.21.1
python312-curses-3.12.9-150600.3.21.1
python312-dbm-3.12.9-150600.3.21.1
python312-devel-3.12.9-150600.3.21.1
python312-idle-3.12.9-150600.3.21.1
python312-tk-3.12.9-150600.3.21.1
python312-tools-3.12.9-150600.3.21.1
openSUSE Leap 15.6
libpython3_12-1_0-3.12.9-150600.3.21.1
libpython3_12-1_0-32bit-3.12.9-150600.3.21.1
python312-3.12.9-150600.3.21.1
python312-32bit-3.12.9-150600.3.21.1
python312-base-3.12.9-150600.3.21.1
python312-base-32bit-3.12.9-150600.3.21.1
python312-curses-3.12.9-150600.3.21.1
python312-dbm-3.12.9-150600.3.21.1
python312-devel-3.12.9-150600.3.21.1
python312-doc-3.12.9-150600.3.21.1
python312-doc-devhelp-3.12.9-150600.3.21.1
python312-idle-3.12.9-150600.3.21.1
python312-testsuite-3.12.9-150600.3.21.1
python312-tk-3.12.9-150600.3.21.1
python312-tools-3.12.9-150600.3.21.1

Описание

During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.


Затронутые продукты
Container bci/python:latest:libpython3_12-1_0-3.12.9-150600.3.21.1
Container bci/python:latest:python312-3.12.9-150600.3.21.1
Container bci/python:latest:python312-base-3.12.9-150600.3.21.1
Container bci/python:latest:python312-devel-3.12.9-150600.3.21.1

Ссылки
Уязвимость SUSE-SU-2025:0883-1